NSE4 Firewall Policies and NAT Practice Question
An administrator needs to configure destination NAT for multiple internal servers using a single public IP address by differentiating based on destination port. The public IP 203.0.113.10 should map to: (A) 10.0.0.1:80 for HTTP, (B) 10.0.0.2:443 for HTTPS. Which TWO configuration steps are required? (Choose two.)
⚠ Common exam trap
Candidates often confuse IP pools (used for source NAT) with VIPs (used for destination NAT), leading candidates to incorrectly select IP pool or Central SNAT options for port forwarding scenarios.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a VIP for HTTP mapping port 80 to 10.0.0.1
A Virtual IP (VIP) is required to map the public IP 203.0.113.10 and destination port 80 to the internal server 10.0.0.1:80. This is the standard FortiGate method for destination NAT (port forwarding) when multiple internal servers share a single public IP, differentiated by destination port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a VIP for HTTP mapping port 80 to 10.0.0.1
Why this is correct
A Virtual IP (VIP) in FortiOS is the standard object for destination NAT, translating an incoming public IP:port pair to a private destination. By mapping the external address's TCP port 80 to 10.0.0.1:80, the administrator configures the DNAT rule that redirects inbound HTTP traffic to the first internal server. This VIP must then be referenced in a firewall policy that allows the traffic and performs the translation.
- ✗
Create an IP pool for the public IP
Why it's wrong here
IP pools in FortiOS are used exclusively for source NAT (SNAT) — selecting a translated source address for outbound sessions or for NATing traffic leaving an interface. They do not inspect or alter the destination IP or port of inbound packets, so creating an IP pool for the public IP would have no effect on inbound HTTP/HTTPS port forwarding. Destination NAT requires a VIP object combined with a firewall policy, never an IP pool.
- ✓
Create a VIP for HTTPS mapping port 443 to 10.0.0.2
Why this is correct
A second VIP is required for the HTTPS service because each VIP object binds a specific external port to a different internal destination; in this case, port 443 must be translated to 10.0.0.2 while port 80 goes to 10.0.0.1. Since the public IP is shared, the destination port disambiguates which internal server should receive the connection. Without a separate VIP, traffic destined to 10.0.0.2:443 would not be translated correctly.
- ✗
Configure policy-based routing for each server
Why it's wrong here
Policy-based routing (PBR) steers packets based on source/destination addresses, interfaces, or other criteria, affecting the next-hop routing decision; it does not perform any address translation. Destination NAT is accomplished by the VIP object and by firewall policies that reference it, with translation occurring before routing. Even if multiple servers require different paths, adding PBR rules would not create the required port mappings and would not replace DNAT.
- ✗
Use Central SNAT with port forwarding
Why it's wrong here
Central SNAT is a global NAT setting that centralizes source NAT configuration, translating source addresses of sessions — typically for outbound traffic — and does not handle inbound port forwarding or destination address replacement. Applying 'port forwarding' through Central SNAT would be a misuse of the feature because forwarding or DNAT is the function of a Virtual IP. If Central NAT is enabled, DNAT is still configured with VIP objects; Central SNAT policies only affect the source field of translated packets.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.